Vulnerability Name: | CVE-2009-3518 (CCN-53515) | ||||||||
Assigned: | 2009-09-30 | ||||||||
Published: | 2009-09-30 | ||||||||
Updated: | 2009-10-02 | ||||||||
Summary: | Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname. | ||||||||
CVSS v3 Severity: | 6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-94 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3518 Source: CCN Type: Retrogod Web Site IBM Installation Manager <= 1.3.0 iim:// uri handler remote code execution exploit - IE Source: MISC Type: Exploit http://retrogod.altervista.org/9sg_ibm_uri.html Source: CCN Type: SA36906 IBM Installation Manager "iim" URI Handling Argument Injection Source: SECUNIA Type: Vendor Advisory 36906 Source: CCN Type: IBM Web site IBM Installation Manager Source: CCN Type: OSVDB ID: 58420 IBM Installation Manager IBMIM.exe iim: URL Library Argument Injection Arbitrary Code Execution Source: CCN Type: BID-36549 IBM Installation Manager 'iim://' URI Handling Remote Code Execution Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2009-2792 Source: XF Type: UNKNOWN installationmanager-ibmim-code-execution(53515) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |